Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Code Analysis | Kitploit
Categories

Code Analysis

Static and dynamic code analysis, SAST, DAST, and code review tools.

Kitploit recommended

Top tools

10 selected
semgrep preview#1

semgrep

GitHubsemgrep/semgrep
16.2k6 days ago
codeql preview#2

codeql

GitHubgithub/codeql
10.1k5h 34m ago
sonarqube preview#3

sonarqube

GitHubsonarsource/sonarqube
11.0k1 day ago
infer preview#4

infer

GitHubfacebook/infer
15.7k1 day ago
ghidra preview#5

ghidra

GitHubnationalsecurityagency/ghidra
71.1k2 days ago
radare2 preview#6

radare2

GitHubradareorg/radare2
24.5k2 days ago
capa preview#7

capa

GitHubmandiant/capa
6.1k1 day ago
bandit preview#8

bandit

GitHubpycqa/bandit
8.2k12 days ago
gosec preview#9

gosec

GitHubsecurego/gosec
8.9k3 days ago
bearer preview#10

bearer

GitHubbearer/bearer
2.7k17 days ago
NewestRelevanceMost popularRecently updated
2079 results
joniles__mpxj_CVE-2020-35460_8-3-4 preview

joniles__mpxj_CVE-2020-35460_8-3-4

GitHubshoucheng3/joniles__mpxj_cve-2020-35460_8-3-4

Exploit for CVE-2020-35460 targeting MPXJ project management library, enabling arbitrary code execution via crafted project files in Java, .Net, and…

static-analysisvulnerability-analysiscode-analysis+2
1 year ago
apache__dolphinscheduler_CVE-2022-34662_2-0-9 preview

apache__dolphinscheduler_CVE-2022-34662_2-0-9

GitHubshoucheng3/apache__dolphinscheduler_cve-2022-34662_2-0-9

Proof-of-concept exploit for CVE-2022-34662 targeting Apache DolphinScheduler, enabling remote code execution via crafted SQL injection in the…

vulnerability-analysiscode-analysisexploitation+3
1 year ago
apache__dolphinscheduler_CVE-2022-26884_2-0-5 preview

apache__dolphinscheduler_CVE-2022-26884_2-0-5

GitHubshoucheng3/apache__dolphinscheduler_cve-2022-26884_2-0-5

Proof-of-concept exploit for CVE-2022-26884 targeting Apache DolphinScheduler, enabling remote code execution via crafted requests to the workflow…

vulnerability-analysiscode-analysisexploitation+3
1 year ago
CVE-2025-2294 preview

CVE-2025-2294

GitHubr0otk3r/cve-2025-2294

Python exploit script for CVE-2025-2294, an unauthenticated Local File Inclusion vulnerability in WordPress Kubio AI Page Builder ≤ 2.5.1. Supports…

vulnerability-analysiscode-analysisexploitation+3
1 year ago
CVE-2023-50564 preview

CVE-2023-50564

GitHubglynzr/cve-2023-50564

Pluck v4.7.18 - Remote Code Execution (RCE)

payload-generationvulnerability-analysiscode-analysis+3
1 year ago
CVE-2025-6586 preview

CVE-2025-6586

GitHubd0n601/cve-2025-6586

Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload

payload-generationvulnerability-analysiscode-analysis+3
1 year ago
CVE-2025-6220 preview

CVE-2025-6220

GitHubd0n601/cve-2025-6220

Ultimate Addons for Contact Form 7 <= 3.5.12 - Authenticated (Administrator+) Arbitrary File Upload via 'save_options'

payload-generationvulnerability-analysiscode-analysis+3
1 year ago
java-cve-2021-29425-tika-xxe preview

java-cve-2021-29425-tika-xxe

GitHubarsalanraja987/java-cve-2021-29425-tika-xxe

Proof-of-concept exploit for CVE-2021-29425, an XML External Entity (XXE) vulnerability in Apache Tika, demonstrating file disclosure and SSRF via…

static-analysisvulnerability-analysiscode-analysis+2
1 year ago
CVE-2023-26563-26564-26565 preview

CVE-2023-26563-26564-26565

GitHubrupturainfosec/cve-2023-26563-26564-26565

Proof-of-concept exploits for three vulnerabilities in Syncfusion file managers: directory traversal leading to arbitrary file read/write/delete, and…

vulnerability-analysiscode-analysisexploitation+3
1 year ago
CVE-2025-50360 preview

CVE-2025-50360

GitHubch1keen/cve-2025-50360

Report and PoC of Heap Buffer Overflow in Pepper Language before version 0.1.1, commit 961a5d9988c5986d563310275adad3fd181b2bb7

static-analysisvulnerability-analysiscode-analysis+3
1 year ago
CVE-2022-28346 preview

CVE-2022-28346

GitHubvincentinttsh/cve-2022-28346

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods…

vulnerability-analysiscode-analysisexploitation+2
4 years ago
CVE-2024-46987 preview

CVE-2024-46987

GitHubramzerk/cve-2024-46987

This Rust PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0).

vulnerability-analysiscode-analysisexploitation+2
7 months ago
DjVuLibre-poc-CVE-2025-53367 preview

DjVuLibre-poc-CVE-2025-53367

GitHubkevinbackhouse/djvulibre-poc-cve-2025-53367

Proof-of-concept exploit for CVE-2025-53367, a vulnerability in the DjVuLibre library. Demonstrates exploitation of a memory corruption bug in DjVu…

static-analysisvulnerability-analysiscode-analysis+3
1 year ago
CVE-2025-9216 preview

CVE-2025-9216

GitHubd0n601/cve-2025-9216

StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.4.0 - Authenticated (Subscriber+)…

vulnerability-analysiscode-analysisexploitation+2
1 year ago
CVE-2025-50460 preview

CVE-2025-50460

GitHubanchor0221/cve-2025-50460

Technical Details and Exploit for CVE-2025-50460

static-analysisvulnerability-analysiscode-analysis+3
1 year ago
Spring4Shell-Python-Firewall-POC preview

Spring4Shell-Python-Firewall-POC

GitHubnickops87/spring4shell-python-firewall-poc

Proof-of-Concept (POC) of a simple firewall in Python designed to mitigate the Spring4Shell (CVE-2022-22965) RCE attack by inspecting and blocking…

defensive-toolsvulnerability-scannerscode-analysis+3
10 months ago
cve-2025-55182-mitigator preview

cve-2025-55182-mitigator

GitHubrashedhasan090/cve-2025-55182-mitigator

CLI scanner that detects likely vulnerable React/Next.js dependencies for CVE-2025-55182 and provides mitigation targets. Supports JSON output and…

defensive-toolsvulnerability-scannerscode-analysis+3
8 months ago
x-stream__xstream_CVE-2021-21345_1-4-15 preview

x-stream__xstream_CVE-2021-21345_1-4-15

GitHubshoucheng3/x-stream__xstream_cve-2021-21345_1-4-15

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

static-analysisvulnerability-analysiscode-analysis+3
1 year ago
Previous1…838485…100Next